WO0219593A2

Service provider-independent sat-based end-user authentication

Abstract

A system and method for verifying the identity of an end-user. The end-user requests to access an external application. The external application sends an authentication request to an authentication server, which generates a random token. The generated token is transmitted to the end-user. The end-user enters the generated token and a personal identification number into a cellular terminal connected to a GSM network. At least the token is encrypted using a secret key stored within the cellular terminal and transmitted through the GSM network to an authentication gateway. The token is decrypted by the authentication gateway using either the same secret key or a key matched to the secret key. The token is then transmitted to the authentication server where the received key is compared to the generated key. The results of the comparison are transmitted to the external application.

WO0219593A2, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 4 independent, 11 dependent

  1. 1
    WE CLAIM:1. A system for authenticating an end-user, comprising: an external application in communication with a first communication device through a first communication network;an authentication server in communication with the external application, the authentication server being adapted to receive an authentication request from the external application in response to an access attempt by the first communication device, and the authentication server generating a token in response to the authentication request and sending the token through the external application to the first communication device;and an authentication gateway in communication with a second communication device through a second communication network, the authentication gateway being adapted to receive a token from the second communication device and to transmit the token to the authentication server, wherein the token received from the authentication gateway is compared to the token generated by the authentication server.
  2. 10
    A method for authenticating an end-user, comprising the steps of:sending an authentication request from an external application to an authentication server;generating a token in the authentication server;presenting the generated token to a first communication device via the external application;generating a cryptographic response based on at least the generated token and a secret key residing within a second communication device;transmitting the cryptographic response from the second communication device to an authentication gateway and the authentication server;decrypting the cryptographic response in the authentication gateway and the authentication server to provide a returned token;comparing the returned token with the generated token;and granting access to the external application if the returned token corresponds to the generated token.
  3. 12
    A network architecture for authenticating an end-user, comprising:at least one gateway connected to at least one communication network, wherein the at least one gateway provides authentication services to the at least one commumcation network;at least one server connected to at least one external application, wherein the at least one server provides authentication services to the at least one external application;and at least one switch connecting the at least one gateway to the at least one server, wherein any of the at least one gateways is accessible, through the at least one switch, by the at least one server.
  4. 14
    A system for authenticating an end-user, comprising:an external application in communication with a first communication device through a first communication network;an authentication server in communication with the external application, the authentication server receiving an authentication request from the external application in response to an access attempt by the first communication device, and the authentication server generating a token in response to the authentication request and sending the token through the external application to the first communication device;and an authentication gateway in communication with a second communication device through a second communication network, the authentication gateway receiving a first message from the second communication device and transmitting a second message to the authentication server;wherein the first message is based on the token and an end-user's PIN code, and the second message is compared to a result of a computation based on the token generated by the authentication server and a PIN code stored in the authentication server and associated with the end-user.